Site hacked - redirected to some other site

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
zahid4848
Joomla! Apprentice
Joomla! Apprentice
Posts: 11
Joined: Wed Jan 04, 2012 10:26 pm

Site hacked - redirected to some other site

Post by zahid4848 » Sat Jul 20, 2013 11:53 pm

Hello

I'm new to this and this never happened to me before

My site - http://www.hstas .org - seems like its been hacked and set to auto-redirect to some dummy site.

Now I have check the ftp of the site and all the files in there are intact and nothing have been deleted.
After looking it carefully there is one file which has been recently updated.
That file is .htaccess sitting in the stats folder, now I have tried deleting and replacing that file and the entire folder. Because I guess stats is a system folder it doesnt allow me to make any changes.

Please help.

Regards,
Z
Last edited by mandville on Sun Jul 21, 2013 12:07 am, edited 1 time in total.
Reason: broke link. posting a complete link to an exploited site can be dangerous

zahid4848
Joomla! Apprentice
Joomla! Apprentice
Posts: 11
Joined: Wed Jan 04, 2012 10:26 pm

Re: Site hacked - redirected to some other site

Post by zahid4848 » Sun Jul 21, 2013 1:35 am

Some Updates -

I was successfully able to restore all the folders and files from my back up - except the stats folder - and as I said thats where that .htaccess file is. It just keep saying I dont have permission to access that file.

I'm thinking If I would be able to restore that file, it should fix the problem - Please correct me if I'm wrong

Please help

Regards,
Z

User avatar
Slackervaara
Joomla! Ace
Joomla! Ace
Posts: 1115
Joined: Sat Aug 13, 2011 6:27 am

Re: Site hacked - redirected to some other site

Post by Slackervaara » Sun Jul 21, 2013 4:49 am

Are there no stats folder, when you try to restore it? If there is a stats folder and files check permissions of them with a ftp-program like FileZilla. Folders should be 755 and files 644.

User avatar
Per Yngve Berg
Joomla! Master
Joomla! Master
Posts: 30923
Joined: Mon Oct 27, 2008 9:27 pm
Location: Romerike, Norway

Re: Site hacked - redirected to some other site

Post by Per Yngve Berg » Sun Jul 21, 2013 6:41 am

Follow the procedure in the Security Checklist

zahid4848
Joomla! Apprentice
Joomla! Apprentice
Posts: 11
Joined: Wed Jan 04, 2012 10:26 pm

Re: Site hacked - redirected to some other site

Post by zahid4848 » Sun Jul 21, 2013 9:02 am

Slackervaara wrote:Are there no stats folder, when you try to restore it? If there is a stats folder and files check permissions of them with a ftp-program like FileZilla. Folders should be 755 and files 644.

The stats folder is there with 705 permission for folder and 644 for files.

I tried to change the permission for the folder to 755 but access denied and couldnt do it.

Thanks for you help

User avatar
Slackervaara
Joomla! Ace
Joomla! Ace
Posts: 1115
Joined: Sat Aug 13, 2011 6:27 am

Re: Site hacked - redirected to some other site

Post by Slackervaara » Sun Jul 21, 2013 9:07 am

Have you checked ownership of the folder and files. Maybe they differ from other files and thats why you can't change permission. You have to Google to figure out how to change ownership.

zahid4848
Joomla! Apprentice
Joomla! Apprentice
Posts: 11
Joined: Wed Jan 04, 2012 10:26 pm

Re: Site hacked - redirected to some other site

Post by zahid4848 » Sun Jul 21, 2013 9:48 am

Slackervaara wrote:Have you checked ownership of the folder and files. Maybe they differ from other files and thats why you can't change permission. You have to Google to figure out how to change ownership.
Yes I have checked the ownership of the folder, I can rename the folder but cant delete.. nor I can delete or rename the files in that folder..?

I still could not figure our where and how this site has been hacked.. guys please help..

User avatar
Slackervaara
Joomla! Ace
Joomla! Ace
Posts: 1115
Joined: Sat Aug 13, 2011 6:27 am

Re: Site hacked - redirected to some other site

Post by Slackervaara » Sun Jul 21, 2013 10:00 am

You could ask the webhost about help with that folder. Run the Forum Post Assistant and post the output here so we can see, if your system have any weakness.

zahid4848
Joomla! Apprentice
Joomla! Apprentice
Posts: 11
Joined: Wed Jan 04, 2012 10:26 pm

Re: Site hacked - redirected to some other site

Post by zahid4848 » Sun Jul 21, 2013 11:57 pm

I did ask my hosting provider, they couldnt do much either..

Please someone have any other idea to fix this?

User avatar
Slackervaara
Joomla! Ace
Joomla! Ace
Posts: 1115
Joined: Sat Aug 13, 2011 6:27 am

Re: Site hacked - redirected to some other site

Post by Slackervaara » Mon Jul 22, 2013 4:12 am

You could try to install the extension Admin Tools and use its feature Fix permissions.

zahid4848
Joomla! Apprentice
Joomla! Apprentice
Posts: 11
Joined: Wed Jan 04, 2012 10:26 pm

Re: Site hacked - redirected to some other site

Post by zahid4848 » Mon Jul 22, 2013 6:32 am

Slackervaara wrote:You could try to install the extension Admin Tools and use its feature Fix permissions.
Okay I have tried that.. installed the plugin - admin tools - ran fixed permissions, even try to manually change permissions for the folder stats.. at the end still can delete that folder... ????

Please help

User avatar
Per Yngve Berg
Joomla! Master
Joomla! Master
Posts: 30923
Joined: Mon Oct 27, 2008 9:27 pm
Location: Romerike, Norway

Re: Site hacked - redirected to some other site

Post by Per Yngve Berg » Mon Jul 22, 2013 11:13 am

I guess the file is hold open by the server and therefore cannot be deleted.


Locked

Return to “Security in Joomla! 1.5”